<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thank you Aditya and Ahmed in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/confusion-related-to-access-list-and-access-group/m-p/2858120#M167130</link>
    <description>&lt;P&gt;Thank you Aditya and Ahmed for your input. I am pretty much sure what you mean &lt;GS id="4032a498-5e1b-4f86-aa70-b84e5390d6c9" ginger_software_uiphraseguid="a9566180-b62d-4fa5-a66a-a8789f606a72" class="GINGER_SOFTWARE_mark"&gt;now but&lt;/GS&gt; let me just clear the air more.&lt;/P&gt;
&lt;P&gt;&lt;GS id="a3643d21-d814-41f6-be7e-e7f73c31be78" ginger_software_uiphraseguid="89f075dc-6de1-4dc0-bc8c-be27e1136eb4" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; need to open ports 1234, 4567, 7890 and so on. &lt;GS id="6fbdc787-7fab-40d1-a34d-c7225ded0313" ginger_software_uiphraseguid="8b414503-97bc-4393-a70a-375c1258fd71" class="GINGER_SOFTWARE_mark"&gt;so&lt;/GS&gt; what will be the command line:&lt;BR /&gt;&lt;GS id="17c2d7b4-e891-4aa7-8725-857ec7d4cb35" ginger_software_uiphraseguid="b8ecdb7b-c345-4562-8efd-e1a4c87f191d" class="GINGER_SOFTWARE_mark"&gt;access&lt;/GS&gt;-list any-name extended permit tcp any hostname 192.168.1.50 &lt;GS id="c4fa13af-5a05-4528-a40c-799b80f8981b" ginger_software_uiphraseguid="b8ecdb7b-c345-4562-8efd-e1a4c87f191d" class="GINGER_SOFTWARE_mark"&gt;eq&lt;/GS&gt; 1234&lt;BR /&gt;&lt;GS id="bc80cf42-93f0-443d-ba9d-6373f08e88b1" ginger_software_uiphraseguid="caf51dab-6e30-4e51-b365-e3dc2fd1ee49" class="GINGER_SOFTWARE_mark"&gt;access&lt;/GS&gt;-list any-name extended permit tcp any hostname 192.168.1.51 &lt;GS id="122eccd3-fc6f-425f-85b5-484fccfa46e0" ginger_software_uiphraseguid="caf51dab-6e30-4e51-b365-e3dc2fd1ee49" class="GINGER_SOFTWARE_mark"&gt;eq&lt;/GS&gt; 4567&lt;BR /&gt;&lt;GS id="10fcf3a7-e251-44d6-8475-1a422b4cc40e" ginger_software_uiphraseguid="881bc609-ef49-49db-92a7-b53ee05eee2e" class="GINGER_SOFTWARE_mark"&gt;access&lt;/GS&gt;-list any-name extended permit tcp any hostname 192.168.1.52 &lt;GS id="8872bd58-63d9-49b6-9cc0-598735ccf300" ginger_software_uiphraseguid="881bc609-ef49-49db-92a7-b53ee05eee2e" class="GINGER_SOFTWARE_mark"&gt;eq&lt;/GS&gt; 7890&lt;/P&gt;
&lt;P&gt;&lt;GS id="b01cfedf-8eee-432d-a127-f73e0d76788f" ginger_software_uiphraseguid="58b765d6-a777-46e2-b68a-d188b0e7740c" class="GINGER_SOFTWARE_mark"&gt;access&lt;/GS&gt;-group any-name in interface outside&lt;/P&gt;
&lt;P&gt;&lt;GS id="f399a63f-64be-489d-9fc2-407c21147c36" ginger_software_uiphraseguid="34bff05c-8908-404e-861b-bb903d0da76e" class="GINGER_SOFTWARE_mark"&gt;should&lt;/GS&gt; this be the command &lt;GS id="6c1f9507-1f32-4c49-8c73-2cf8229df5ed" ginger_software_uiphraseguid="34bff05c-8908-404e-861b-bb903d0da76e" class="GINGER_SOFTWARE_mark"&gt;line line&lt;/GS&gt; or &lt;GS id="cc928aa9-c664-46d8-b676-fe0fbd48191a" ginger_software_uiphraseguid="34bff05c-8908-404e-861b-bb903d0da76e" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; can change the name of &lt;GS id="5f964ec7-4427-4b33-ab3e-b4244f4ae911" ginger_software_uiphraseguid="34bff05c-8908-404e-861b-bb903d0da76e" class="GINGER_SOFTWARE_mark"&gt;access&lt;/GS&gt;-list in every &lt;GS id="cc5f99ec-0520-4320-aa71-a794f90e9e65" ginger_software_uiphraseguid="34bff05c-8908-404e-861b-bb903d0da76e" class="GINGER_SOFTWARE_mark"&gt;steps&lt;/GS&gt;?&lt;BR /&gt;What if &lt;GS id="b7e91cef-850f-4f72-adb7-3a76c7e394ee" ginger_software_uiphraseguid="67415813-61af-474b-a031-e25704bbe87a" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; have to open new ports 9012, should the access group name be &lt;GS id="f1a574b4-3666-4f06-8696-b3341bb9a5e0" ginger_software_uiphraseguid="67415813-61af-474b-a031-e25704bbe87a" class="GINGER_SOFTWARE_mark"&gt;same&lt;/GS&gt;? What about the access-list, should the name be same for every access-rule we make?&lt;/P&gt;</description>
    <pubDate>Thu, 19 May 2016 03:01:34 GMT</pubDate>
    <dc:creator>diwakar410</dc:creator>
    <dc:date>2016-05-19T03:01:34Z</dc:date>
    <item>
      <title>Confusion related to access-list and access-group</title>
      <link>https://community.cisco.com/t5/network-security/confusion-related-to-access-list-and-access-group/m-p/2858117#M167127</link>
      <description>&lt;P&gt;Hello there,&lt;/P&gt;
&lt;P&gt;I have &lt;GS id="f8754ff1-f61a-499c-985f-653d78e354ef" ginger_software_uiphraseguid="4ae14ee9-88c4-402b-be2b-97b3641e1aae" class="GINGER_SOFTWARE_mark"&gt;cisco&lt;/GS&gt;&amp;nbsp;ASA 5515-x version 9.2.2 and ASDM version 7.2.&lt;/P&gt;
&lt;P&gt;The inside interface and IP is 192.168.1.1/24 and outside interface is x.x.x.x.&lt;/P&gt;
&lt;P&gt;I had opened &amp;nbsp;certain ports like 1234,4567,8900 and so on.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Today &lt;GS id="bff5aec2-25e4-4ec1-90dd-22cac795ca62" ginger_software_uiphraseguid="86fcc053-adef-4d21-89af-f24759ee4c10" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; needed to open 7000 &lt;GS id="35ee6533-0dc2-4cd3-a119-fc5f564996b0" ginger_software_uiphraseguid="86fcc053-adef-4d21-89af-f24759ee4c10" class="GINGER_SOFTWARE_mark"&gt;port&lt;/GS&gt; and &lt;GS id="e591bcfb-91bf-479b-bb9e-08a4733c3863" ginger_software_uiphraseguid="86fcc053-adef-4d21-89af-f24759ee4c10" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; created NAT rule and access-list as well. Then &lt;GS id="08b0d565-13c1-4ff2-ad88-c6d5a45d80eb" ginger_software_uiphraseguid="572f1763-1a42-464b-9b69-f0c286a28b89" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; created the access-group with &lt;GS id="bad1c6fd-09f8-4855-80b5-601b0254c03a" ginger_software_uiphraseguid="572f1763-1a42-464b-9b69-f0c286a28b89" class="GINGER_SOFTWARE_mark"&gt;command&lt;/GS&gt;:&lt;/P&gt;
&lt;P&gt;"&lt;GS id="4b42f0b8-c54f-41c4-9b2f-505fe7444ce6" ginger_software_uiphraseguid="81988fc8-0a77-481a-a9fb-834295819e67" class="GINGER_SOFTWARE_mark"&gt;access&lt;/GS&gt;-group port-forward in interface outside " and all of a sudden &lt;GS id="808f2626-c4fe-44e9-b8cb-6de53e2890ae" ginger_software_uiphraseguid="81988fc8-0a77-481a-a9fb-834295819e67" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; found all other access-list rules are gone and only &lt;GS id="e897ce1e-8c31-48f1-ad30-51749f415006" ginger_software_uiphraseguid="81988fc8-0a77-481a-a9fb-834295819e67" class="GINGER_SOFTWARE_mark"&gt;existing&lt;/GS&gt; rule &lt;GS id="8a3c2e28-407c-4944-858b-906c0886b4cf" ginger_software_uiphraseguid="81988fc8-0a77-481a-a9fb-834295819e67" class="GINGER_SOFTWARE_mark"&gt;for&lt;/GS&gt; 7000 exists.&lt;/P&gt;
&lt;P&gt;Do we need to specify only one access-group rule for all the ports in the same interface?&lt;BR /&gt;Should the access-group for opening ports like 1234,4567 and so on should have the same access-group name?&lt;/P&gt;
&lt;P&gt;Please help.&lt;/P&gt;
&lt;P&gt;Thank you in &lt;GS id="91176328-2cf3-4a48-bef4-05bd18e64c79" ginger_software_uiphraseguid="25383804-e0a5-4ccf-87a1-60cfa2c37220" class="GINGER_SOFTWARE_mark"&gt;advnace&lt;/GS&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 07:45:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/confusion-related-to-access-list-and-access-group/m-p/2858117#M167127</guid>
      <dc:creator>diwakar410</dc:creator>
      <dc:date>2019-03-12T07:45:32Z</dc:date>
    </item>
    <item>
      <title>Hi Diwakar,</title>
      <link>https://community.cisco.com/t5/network-security/confusion-related-to-access-list-and-access-group/m-p/2858118#M167128</link>
      <description>&lt;P&gt;Hi Diwakar,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;G class="gr_ gr_44 gr-alert gr_gramm gr_run_anim Punctuation only-ins replaceWithoutSep" id="44" data-gr-id="44"&gt;Yes&lt;/G&gt; you are correct.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Only one access-group can be applied on &lt;G class="gr_ gr_56 gr-alert gr_gramm gr_run_anim Grammar only-ins doubleReplace replaceWithoutSep" id="56" data-gr-id="56"&gt;interface&lt;/G&gt; in one direction.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So if you need to modify any ACL rules you need to do on the same access-list which in turn would be &lt;G class="gr_ gr_160 gr-alert gr_spell gr_run_anim ContextualSpelling multiReplace" id="160" data-gr-id="160"&gt;binded&lt;/G&gt; to the access-group on the interface.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In your case only the access-group would have been removed, the access-list would be still on the ASA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2016 12:21:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/confusion-related-to-access-list-and-access-group/m-p/2858118#M167128</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-05-17T12:21:33Z</dc:date>
    </item>
    <item>
      <title>You can revert your changes</title>
      <link>https://community.cisco.com/t5/network-security/confusion-related-to-access-list-and-access-group/m-p/2858119#M167129</link>
      <description>&lt;P&gt;You can revert your changes by reapplying the previous access list:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;'access-group outside_access_in in interface outside' just make sure that your previous access list name was 'outside_access_in'. Once it is applied then you can add in the same access list for port 7000.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Ahmed&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2016 13:50:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/confusion-related-to-access-list-and-access-group/m-p/2858119#M167129</guid>
      <dc:creator>ahmed-ejaz</dc:creator>
      <dc:date>2016-05-17T13:50:58Z</dc:date>
    </item>
    <item>
      <title>Thank you Aditya and Ahmed</title>
      <link>https://community.cisco.com/t5/network-security/confusion-related-to-access-list-and-access-group/m-p/2858120#M167130</link>
      <description>&lt;P&gt;Thank you Aditya and Ahmed for your input. I am pretty much sure what you mean &lt;GS id="4032a498-5e1b-4f86-aa70-b84e5390d6c9" ginger_software_uiphraseguid="a9566180-b62d-4fa5-a66a-a8789f606a72" class="GINGER_SOFTWARE_mark"&gt;now but&lt;/GS&gt; let me just clear the air more.&lt;/P&gt;
&lt;P&gt;&lt;GS id="a3643d21-d814-41f6-be7e-e7f73c31be78" ginger_software_uiphraseguid="89f075dc-6de1-4dc0-bc8c-be27e1136eb4" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; need to open ports 1234, 4567, 7890 and so on. &lt;GS id="6fbdc787-7fab-40d1-a34d-c7225ded0313" ginger_software_uiphraseguid="8b414503-97bc-4393-a70a-375c1258fd71" class="GINGER_SOFTWARE_mark"&gt;so&lt;/GS&gt; what will be the command line:&lt;BR /&gt;&lt;GS id="17c2d7b4-e891-4aa7-8725-857ec7d4cb35" ginger_software_uiphraseguid="b8ecdb7b-c345-4562-8efd-e1a4c87f191d" class="GINGER_SOFTWARE_mark"&gt;access&lt;/GS&gt;-list any-name extended permit tcp any hostname 192.168.1.50 &lt;GS id="c4fa13af-5a05-4528-a40c-799b80f8981b" ginger_software_uiphraseguid="b8ecdb7b-c345-4562-8efd-e1a4c87f191d" class="GINGER_SOFTWARE_mark"&gt;eq&lt;/GS&gt; 1234&lt;BR /&gt;&lt;GS id="bc80cf42-93f0-443d-ba9d-6373f08e88b1" ginger_software_uiphraseguid="caf51dab-6e30-4e51-b365-e3dc2fd1ee49" class="GINGER_SOFTWARE_mark"&gt;access&lt;/GS&gt;-list any-name extended permit tcp any hostname 192.168.1.51 &lt;GS id="122eccd3-fc6f-425f-85b5-484fccfa46e0" ginger_software_uiphraseguid="caf51dab-6e30-4e51-b365-e3dc2fd1ee49" class="GINGER_SOFTWARE_mark"&gt;eq&lt;/GS&gt; 4567&lt;BR /&gt;&lt;GS id="10fcf3a7-e251-44d6-8475-1a422b4cc40e" ginger_software_uiphraseguid="881bc609-ef49-49db-92a7-b53ee05eee2e" class="GINGER_SOFTWARE_mark"&gt;access&lt;/GS&gt;-list any-name extended permit tcp any hostname 192.168.1.52 &lt;GS id="8872bd58-63d9-49b6-9cc0-598735ccf300" ginger_software_uiphraseguid="881bc609-ef49-49db-92a7-b53ee05eee2e" class="GINGER_SOFTWARE_mark"&gt;eq&lt;/GS&gt; 7890&lt;/P&gt;
&lt;P&gt;&lt;GS id="b01cfedf-8eee-432d-a127-f73e0d76788f" ginger_software_uiphraseguid="58b765d6-a777-46e2-b68a-d188b0e7740c" class="GINGER_SOFTWARE_mark"&gt;access&lt;/GS&gt;-group any-name in interface outside&lt;/P&gt;
&lt;P&gt;&lt;GS id="f399a63f-64be-489d-9fc2-407c21147c36" ginger_software_uiphraseguid="34bff05c-8908-404e-861b-bb903d0da76e" class="GINGER_SOFTWARE_mark"&gt;should&lt;/GS&gt; this be the command &lt;GS id="6c1f9507-1f32-4c49-8c73-2cf8229df5ed" ginger_software_uiphraseguid="34bff05c-8908-404e-861b-bb903d0da76e" class="GINGER_SOFTWARE_mark"&gt;line line&lt;/GS&gt; or &lt;GS id="cc928aa9-c664-46d8-b676-fe0fbd48191a" ginger_software_uiphraseguid="34bff05c-8908-404e-861b-bb903d0da76e" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; can change the name of &lt;GS id="5f964ec7-4427-4b33-ab3e-b4244f4ae911" ginger_software_uiphraseguid="34bff05c-8908-404e-861b-bb903d0da76e" class="GINGER_SOFTWARE_mark"&gt;access&lt;/GS&gt;-list in every &lt;GS id="cc5f99ec-0520-4320-aa71-a794f90e9e65" ginger_software_uiphraseguid="34bff05c-8908-404e-861b-bb903d0da76e" class="GINGER_SOFTWARE_mark"&gt;steps&lt;/GS&gt;?&lt;BR /&gt;What if &lt;GS id="b7e91cef-850f-4f72-adb7-3a76c7e394ee" ginger_software_uiphraseguid="67415813-61af-474b-a031-e25704bbe87a" class="GINGER_SOFTWARE_mark"&gt;i&lt;/GS&gt; have to open new ports 9012, should the access group name be &lt;GS id="f1a574b4-3666-4f06-8696-b3341bb9a5e0" ginger_software_uiphraseguid="67415813-61af-474b-a031-e25704bbe87a" class="GINGER_SOFTWARE_mark"&gt;same&lt;/GS&gt;? What about the access-list, should the name be same for every access-rule we make?&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2016 03:01:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/confusion-related-to-access-list-and-access-group/m-p/2858120#M167130</guid>
      <dc:creator>diwakar410</dc:creator>
      <dc:date>2016-05-19T03:01:34Z</dc:date>
    </item>
    <item>
      <title>Hi Diwakar,</title>
      <link>https://community.cisco.com/t5/network-security/confusion-related-to-access-list-and-access-group/m-p/2858121#M167131</link>
      <description>&lt;P&gt;Hi Diwakar,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The name of the access-list will always be the same.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2016 03:23:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/confusion-related-to-access-list-and-access-group/m-p/2858121#M167131</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-05-19T03:23:44Z</dc:date>
    </item>
    <item>
      <title>This can either be through</title>
      <link>https://community.cisco.com/t5/network-security/confusion-related-to-access-list-and-access-group/m-p/2858122#M167132</link>
      <description>&lt;P&gt;This can either be through command line or can be done through ASDM, though ASDM will be much easier. The best way to do it is by creating objects i-e SERVER1 IP 192.168.1.50, then in the access policies create a new rule and use these objects instead of IP addresses (just a neater way of doing it) and open the required posts.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;There is only a single access-group applied on every firewall interface i-e inside_access_in on the inside interface (this is by default) outside_access_in on the outside interface.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you want to manually add an entry in the list then first check what is the name of access list applied on the interface, if its outside_access_in then just add another entry:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Example:&lt;/P&gt;
&lt;P&gt;access-list outside_access_in extended permit icmp any any echo-reply&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I hope the above helps.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Ahmed&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2016 08:06:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/confusion-related-to-access-list-and-access-group/m-p/2858122#M167132</guid>
      <dc:creator>ahmed-ejaz</dc:creator>
      <dc:date>2016-05-19T08:06:18Z</dc:date>
    </item>
  </channel>
</rss>

